it_gsr
asked on
How to Remove TR/Dropper.Gen Virus
Hello,
I realised that my file server shares have all vanished. Checks revealled that the folders have become hidden and read-only and replacemenent exe's with the same name as the folders are not available instead.
My read around indicates this is Dropper virus or trojan. My antivirus program, Avira, could not detect this virus.
I would like a step by step manual way of removing this virus and restoring the files and folders on my server to their original status.
I realised that my file server shares have all vanished. Checks revealled that the folders have become hidden and read-only and replacemenent exe's with the same name as the folders are not available instead.
My read around indicates this is Dropper virus or trojan. My antivirus program, Avira, could not detect this virus.
I would like a step by step manual way of removing this virus and restoring the files and folders on my server to their original status.
Hm, intresting. Maybe it's new modification. http://www.avira.com/en/support-threats-description/tid/3647/tr_dropper.gen.html Is your avira updated?
Try this cleaner. Doesn'r required install http://www.freedrweb.com/download+cureit/
Try this cleaner. Doesn'r required install http://www.freedrweb.com/download+cureit/
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Sudeep
Followed the instructions and these are the logs.
I am yet to run step 3.
I notice that not long after the foldes are unidden by Roguekiller, the problem resurfaces. I assume it could be a user re-infecting the system.
Any way I can prevent reinfections?
RKreport-2--SC-01042013-02d0847.txt
mbam-log-2013-01-04--09-13-06-.txt
RKreport-1--S-01042013-02d0825.txt
Followed the instructions and these are the logs.
I am yet to run step 3.
I notice that not long after the foldes are unidden by Roguekiller, the problem resurfaces. I assume it could be a user re-infecting the system.
Any way I can prevent reinfections?
RKreport-2--SC-01042013-02d0847.txt
mbam-log-2013-01-04--09-13-06-.txt
RKreport-1--S-01042013-02d0825.txt
Get a descent antivirus or internet security, I'm using Kaspersky Internet security and haven't had any virus at all even though I visit some infected sites intentionally but Kaspersky even checks the website that you visit for infection. and also downloads even if they are compressed in ZIP format.
Also you may want to set your server behind a strict firewall like Cisco, SonicWALL for hardware or pfsense, untangle iptable for Software firewalls.
I'm using pfsense over 25 servers with IP blocker for spammers and Snort for network intrusion detection.
If you just have one server then you can set it for both your server and clients as well.
Also you may want to set your server behind a strict firewall like Cisco, SonicWALL for hardware or pfsense, untangle iptable for Software firewalls.
I'm using pfsense over 25 servers with IP blocker for spammers and Snort for network intrusion detection.
If you just have one server then you can set it for both your server and clients as well.
http://www.ehow.com/how_7308616_remove-tr_dropper-virus.html